Skip to content
COOEY

EXPOSURES › CVE-2026-41699

CVE-2026-41699

HIGH
DETAIL
SourceNVD · cve Published2026-06-11 CVSS8.1 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-41699 ↗

▸ RECOMMENDED ACTION  Patch the affected products and confirm your instances are covered.

DESCRIPTION

Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the application exposes a paginated (Connection) field and the classpath contains specific classes that can be leveraged during deserialization. Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
VMware Government Services (VGS)
VMware, Inc.
Authorized
Workspace ONE
VMware, Inc.
Authorized